Package
dependency-track-apiserver-4
Component
logback-core
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable logback classes are bundled inside the prebuilt alpine-executable-war overlay that assembles the embedded application server. This overlay is pinned to the framework release the application requires, so the bundled logback version cannot be overridden through dependency management; remediation is pending an upstream release of the overlay built against the patched logback.
Status